2025 CVE Vulnerabilities

45,233 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10823LOW3.3A vulnerability was found in axboe fio up to 3.41. This affects the function str_buffer_pattern_cb of the file options.c...
CVE-2025-10822MEDIUM4.3A vulnerability has been found in fuyang_lipengjun platform 1.0. The impacted element is the function SysSmsLogControlle...
CVE-2025-43814MEDIUM6.5In Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, ...
CVE-2025-43810MEDIUM4.3Insecure Direct Object Reference (IDOR) vulnerability with commerce order notes in Liferay Portal 7.3.5 through 7.4.3.11...
CVE-2025-10821MEDIUM4.3A flaw has been found in fuyang_lipengjun platform 1.0. The affected element is the function TopicCategoryController of ...
CVE-2025-10820MEDIUM4.3A vulnerability was detected in fuyang_lipengjun platform 1.0. Impacted is the function TopicController of the file /top...
CVE-2025-10819MEDIUM4.3A security vulnerability has been detected in fuyang_lipengjun platform 1.0. This issue affects the function UserCouponC...
CVE-2025-43806MEDIUM4.3Batch Engine in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2...
CVE-2025-10817CRITICAL9.8A weakness has been identified in Campcodes Online Learning Management System 1.0. This vulnerability affects unknown co...
CVE-2025-10816CRITICAL9.8A security flaw has been discovered in Jinher OA 2.0. This affects an unknown part of the file /c6/Jhsoft.Web.module/Too...
CVE-2025-59535MEDIUM6.5DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v...
CVE-2025-59532HIGH8.6Codex CLI is a coding agent from OpenAI that runs locally. In versions 0.2.0 to 0.38.0, due to a bug in the sandbox conf...
CVE-2025-57205MEDIUM5.4iNiLabs School Express (SMS Express) 6.2 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the content...
CVE-2025-57204MEDIUM5.4Stocky POS with Inventory Management & HRM (ui-lib) version 5.0 is affected by a Stored Cross-Site Scripting (XSS) vulne...
CVE-2025-47910MEDIUM5.4When using http.CrossOriginProtection, the AddInsecureBypassPattern method can unexpectedly bypass more requests than in...
CVE-2025-10815HIGH8.8A vulnerability was identified in Tenda AC20 up to 16.03.08.12. Affected by this issue is the function strcpy of the fil...
CVE-2025-10814HIGH8.8A vulnerability was determined in D-Link DIR-823X 240126/240802/250416. Affected by this vulnerability is an unknown fun...
CVE-2025-59528CRITICAL10Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vu...
CVE-2025-59527HIGH7.5Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, a Server-Side...
CVE-2025-59526LOW2.7mailgen is a Node.js package that generates responsive HTML e-mails for sending transactional mail. Prior to version 2.0...
CVE-2025-59434CRITICAL9.6Flowise is a drag & drop user interface to build a customized large language model flow. Prior to August 2025 Cloud-Host...
CVE-2025-59433MEDIUM5.3Conventional Changelog generates changelogs and release notes from a project's commit messages and metadata. Prior to ve...
CVE-2025-59432MEDIUM6.6SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security L...
CVE-2025-57203MEDIUM4.8MagicProject AI version 9.1 is affected by a Cross-Site Scripting (XSS) vulnerability within the chatbot generation feat...
CVE-2025-10813CRITICAL9.8A vulnerability was found in code-projects Hostel Management System 1.0. Affected is an unknown function of the file /ju...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now